Splunk Search

How to ignore a field from search if the value is null, and then search based on the second input.?

kuriakose
Explorer

How to ignore a field from search if the value is null, search based on the second input.?
I have two inputs and this search will work only if i have some value in both the fields. I need the result, even if one value is null.

1.png

name="$field4$" OR EmpID="$field5$"

Found a similar one here,
but this did not resolve my issue.

Appreciate the help in advance.

https://community.splunk.com/t5/Getting-Data-In/How-to-omit-a-field-from-search-on-a-text-input-if-t...

Labels (1)
0 Karma

kuriakose
Explorer

I could sort out this issue by trying |search ($test1$ $test2$). 

Now the search is giving the results even if one input is null. 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Doesn't this just do ($test1$ AND $test2$)?

0 Karma

kuriakose
Explorer

I have field values, name and EmpID in my index. The above search will not work if I am giving only a single input. I have to give both the inputs then only its working. which I don't want. Sometime I will have only one input.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Try setting the default to * and/or in the change handler for the text input set a token to * if the input is empty and use those tokens in your search

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Have your inputs set a new token which includes the name= if the value of the input is not empty otherwise set it to an empty string or perhaps unset it. Then use the whole of the new token(s) in your search.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...